Filter also on username in AuthManager.active_authenticators().

Requested by @dctrud. With respect to previous implementation, email and
username are passed as separate parameters.
This commit is contained in:
Nicola Soranzo
2015-05-06 11:39:43 +01:00
parent 4658bfe4f2
commit f4b648d331
2 changed files with 19 additions and 12 deletions
+6 -2
View File
@@ -2,7 +2,11 @@
<auth>
<!--<authenticator>
<type>ldap</type>
<filter>'{email}'.endswith('@example.com')</filter>
-->
<!-- Filter users for which this authenticator applies. This is a Python
expression which is evaluated after replacing instances of {email}
and {username} with the corresponding user's values. -->
<!-- <filter>'{email}'.endswith('@example.com')</filter>
<options>
<auto-register>True</auto-register>
<server>ldap://dc1.example.com</server>
@@ -20,7 +24,7 @@
<auto-register-username>{sAMAccountName}</auto-register-username>
<auto-register-email>{mail}</auto-register-email>
-->
<!-- To allow login with username instead of email -->
<!-- To allow login with username instead of email, default is False -->
<!-- <login-use-username>True</login-use-username>
</options>
</authenticator>
+13 -10
View File
@@ -64,7 +64,7 @@ class AuthManager(object):
"""Checks if the provided email/username is allowed to register."""
message = ''
status = 'done'
for provider, options in self.active_authenticators(email, password):
for provider, options in self.active_authenticators(email, username, password):
allow_reg = _get_tri_state(options, 'allow-register', True)
if allow_reg is None: # i.e. challenge
auth_result, msg = provider.authenticate(email, username, password, options)
@@ -87,14 +87,17 @@ class AuthManager(object):
Checks the username/email & password using auth providers in order.
If a match is found, returns the 'auto-register' option for that provider.
"""
for provider, options in self.active_authenticators(login, password):
if '@' in login:
email = login
username = None
else:
email = None
username = login
for provider, options in self.active_authenticators(email, username, password):
if provider is None:
log.debug( "Unable to find module: %s" % options )
else:
if '@' in login:
auth_result, auto_email, auto_username = provider.authenticate(login, None, password, options)
else:
auth_result, auto_email, auto_username = provider.authenticate(None, login, password, options)
auth_result, auto_email, auto_username = provider.authenticate(email, username, password, options)
auto_email = str(auto_email).lower()
auto_username = str(auto_username).lower()
if auth_result is True:
@@ -117,7 +120,7 @@ class AuthManager(object):
def check_password(self, user, password):
"""Checks the username/email and password using auth providers."""
for provider, options in self.active_authenticators(user.email, password):
for provider, options in self.active_authenticators(user.email, user.username, password):
if provider is None:
log.debug( "Unable to find module: %s" % options )
else:
@@ -132,7 +135,7 @@ class AuthManager(object):
"""Checks that auth provider allows password changes and current_password
matches.
"""
for provider, options in self.active_authenticators(user.email, current_password):
for provider, options in self.active_authenticators(user.email, user.username, current_password):
if provider is None:
log.debug( "Unable to find module: %s" % options )
else:
@@ -146,7 +149,7 @@ class AuthManager(object):
return (False, 'Password change not supported')
return (False, 'Invalid current password')
def active_authenticators(self, email, password):
def active_authenticators(self, email, username, password):
"""Yields AuthProvider instances for the provided configfile that match the
filters.
"""
@@ -154,7 +157,7 @@ class AuthManager(object):
for authenticator in self.authenticators:
filter_template = authenticator.filter_template
if filter_template:
filter_str = filter_template.format(email=email, password=password)
filter_str = filter_template.format(email=email, username=username, password=password)
passed_filter = eval(filter_str, {"__builtins__": None}, {'str': str})
if not passed_filter:
continue # skip to next